HTTP: Inductive Automation Ignition project getDiffs Insecure Deserialization

This signature detects attempts to exploit a known vulnerability against Inductive Automation Ignition. A successful attack can lead to arbitrary code execution.

Extended Description

The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9.14), allowing an attacker to obtain sensitive information.

Affected Products

Inductiveautomation ignition_gateway

Short Name
HTTP:CTS:IA-GTDIFF-INSEC-DSRLZE
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Automation CVE-2020-10644 Deserialization Ignition Inductive Insecure getDiffs project
Release Date
02/13/2023
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

Sigpack Version
3575
False Positive
Unknown
Vendors

Inductiveautomation

Found a potential security threat?